On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force. It moves the obligations for high-risk systems under Annex III from 2 August 2026 to 2 December 2027.
That postpones one part, not the whole. The transparency obligations under Article 50 have applied since 2 August 2026, and that date was left untouched.
For Swiss companies this means: part of the obligations already applies, the larger part arrives in 16 months. Anyone who uses AI in recruiting is affected, including where no EU location is involved.
What is the EU AI Act?
The EU AI Act is the world's first comprehensive AI regulation. It has been in force since August 2024 and is being phased in. Instead of regulating AI as a whole, it classifies applications by risk and ties obligations to each class.
The regulation distinguishes these risk classes:
- Prohibited practices (in force since 2 Feb 2025): social scoring, manipulative AI, emotion recognition in the workplace, among others
- General Purpose AI models (obligations since 2 Aug 2025): large foundation models such as GPT, Gemini, Claude
- Systems with transparency obligations (applicable since 2 Aug 2026): chatbots, generated content, deepfakes
- High-risk systems (new deadline 2 Dec 2027): AI in hiring and personnel decisions, in education, in healthcare, in law enforcement and in further sensitive applications
- High-risk systems under Annex I (new deadline 2 Aug 2028): AI as a safety component in regulated products, for instance machinery or medical devices. Not relevant to recruiting, but part of the same postponement.
The fines are substantial. Breaches of prohibited practices can cost up to EUR 35 million or 7% of global annual turnover. For high-risk breaches, the limit is EUR 15 million or 3% of turnover. False or misleading information given to authorities carries up to EUR 7.5 million or 1%.
For SMEs and start-ups, the lower of the two figures applies in each case, for everyone else the higher one. That is set out in Article 99(6) and makes the decisive difference for a mid-sized Swiss company.
What has applied since 2 August 2026
Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have been applicable. They were explicitly not postponed. Only the obligations for high-risk systems were.
Two of these points are directly relevant for recruiting teams:
Anyone using a chatbot in first contact must disclose that candidates are speaking to an AI system and not to a person. This applies as soon as that is not already obvious from the context.
Anyone operating a system that recognises emotions or categorises people on the basis of biometric data must inform the people concerned. In recruiting, emotion recognition has been prohibited since 2 February 2025 in any case, so the duty to inform only bites outside that prohibition.
For providers of generative AI, the machine-readable marking of synthetic content under Article 50(2) is added. There is a grace period here: systems placed on the market before 2 August 2026 only have to meet this marking requirement from 2 December 2026. The human-readable disclosure, by contrast, applies with no transition period.
Takeaway: fines did not become new on that date. The penalty provisions of the EU AI Act have applied since 2 August 2025. What is missing until 2 December 2027 is not the power to fine, but the high-risk obligation you could breach.
Why recruiting is classified as high-risk
Recruiting is named explicitly in Annex III, point 4(a) of the EU AI Act. The wording is more precise than many expect. It covers AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter applications and to evaluate candidates.
The targeted delivery of job advertisements therefore comes first, ahead of the selection decision. That surprises many HR teams, because the word high-risk makes them think of the decision at the end of the process. The legislator starts earlier, namely where it is decided who gets to see a vacancy at all.
In practice, this covers:
- Algorithmic targeting of job advertisements, that is, the question of which people an ad is shown to
- Automated filtering and ranking of CVs
- AI-supported scoring of cover letters or video interviews
- Chatbots that pre-screen in first contact
- Tools that derive suitability predictions from personality tests
Several applications in recruiting have been prohibited since February 2025. Emotion recognition in video interviews, social scoring of candidates, inference of sensitive characteristics from biometric data. These obligations apply immediately. They have not been postponed.
To see why bias risks in recruiting are taken so seriously, consider a simple example. A 2026 British survey had 1,000 people evaluate two identical, AI-written CVs, one under the name James Clarke, one under Emily Clarke. Emily's CV had its trustworthiness doubted 22% more often and its competence questioned twice as often. The AI had not written any bias. People nevertheless read one into it.
«The AI had not written any bias. People nevertheless read one into it.»
Source: Zehra Chatoo / Code For Good Now, 2026. Fortune article
Does the EU AI Act apply to Swiss companies?
The honest answer: it depends. In most larger Swiss companies, at least one of the three following paths is in play.
Path 1: Direct application of the EU AI Act
Swiss companies fall directly under the EU AI Act when they use AI recruiting tools at EU sites or pre-screen EU candidates with AI. Swiss providers of AI recruiting tools with EU customers are also affected. The EU AI Act follows the same market-location logic as the GDPR.
Path 2: Indirect application through the revised Swiss Data Protection Act
The revised Swiss Data Protection Act has been in force since September 2023. Article 21 regulates automated individual decisions with legal effect or significant impact. Affected persons have the right to information, to express their position, and to a human review. Anyone using AI in recruiting to pre-select candidates falls under this rule. Independently of the EU AI Act.
Path 3: Future application via the Council of Europe's AI Convention
Switzerland signed the Council of Europe's Framework Convention on Artificial Intelligence on 27 March 2025, but has not yet ratified it. On 12 February 2025, the Federal Council decided how it intends to proceed: no dedicated Swiss AI act along EU lines, but a sectoral approach with targeted adjustments to transparency, data protection, non-discrimination and supervision.
The Federal Department of Justice and Police is preparing a consultation draft on this by the end of 2026, while the Federal Department of the Environment, Transport, Energy and Communications works on an implementation plan for the legally non-binding measures. As things stand today, the consultation has not yet been opened. What will then enter Swiss law, and when, is open. The end of this decade is realistic. But the direction is set.
Six steps for HR teams
Anyone moving in a structured way now has about 16 months until the high-risk deadline in December 2027. Enough to act deliberately rather than in a rush. The following six steps form the operational core.
Step 1: Inventory your AI tools in recruiting
Start with an honest stock-take. Which AI functions are currently active in your recruiting? Office AI, ATS features, chatbots, generative AI for job-ad copy, automated reply emails, screening tools. The features used unconsciously count too. You'll be surprised what shows up.
Step 2: Risk classification under Annex III
Sort the identified functions by the EU AI Act criteria. Which ones support or replace selection decisions? Which analyse personal traits? Which make automated pre-selections? Those fall under high-risk. Purely administrative AI such as automated calendar booking does not.
Step 3: Vendor due diligence
Approach your vendors actively. Which compliance measures are planned? Which declaration of conformity will be provided? Which documentation can you request from your side? Whoever asks in time has the trail in case of conflict. Whoever waits will learn very quickly that not all vendors have answers.
Specific compliance signals to look for: documented data protection compliance under revDSG and GDPR, Swiss data residency, traceable evaluation trails. At Refline, we've worked to that standard for years, not because the EU AI Act now demands it, but because Swiss HR has always needed it.
Step 4: Establish human oversight
High-risk AI requires human oversight. Clarify who checks AI output in recruiting, who decides responsibly and who documents. When an AI pre-ranks candidates, a person must make the final selection and be able to justify it transparently.
That's exactly what an ATS is built for: every decision, every status change, every evaluation step is documented in a structured way. At Refline, this audit trail is not an add-on, it's part of the core architecture.
Step 5: Transparency inside and out
Inform candidates when AI takes part in the selection process. Inform employees when AI is used in internal decisions. Transparency is not just a legal obligation, it's the basis for trust. Anyone hiding AI risks more than fines.
Step 6: Structured evaluation as the foundation
The most important step is also the least spectacular. Structured interviews, documented evaluation grids, four-eyes principle in pre-selection. These practices work twice over: against bias and as the audit trail compliance needs. A well-run ATS provides exactly that trail, because it structures decisions anyway.
How to document evaluations traceably
Traceable means: for every decision it is clear who evaluated, on what basis and when. Most processes fail at this not for lack of will, but because of where things are filed. Feedback sits in email threads, in individual people's notes or in an Excel list nobody can find later.
In Refline, the feedback of everyone involved is collected directly in the candidate file and stays transparently visible there. The documentation is created as the process runs and does not have to be reconstructed after the fact.
That does not replace a legal review. But it answers the question that comes first with any documentation duty: where is it actually written down?
Outlook: what comes next?
The deadline shift is not the end of the movement, only a stage.
At the EU level, the Digital Omnibus on AI has been in force since 27 July 2026. What is still open are the European Commission's announced guidelines on high-risk classification. Anyone who wants to know what matters in the coming months should follow the official documents.
In Switzerland, the legal frame will shift after the signing of the Council of Europe Convention. The consultation planned for the end of 2026 will have to address the interface with the revDSG, with sectoral regulations and with industry guidelines. FINMA has already set out expectations for regulated sectors. Other supervisory authorities will follow.
In the market, a standard for AI-ready HR tools is emerging. The first declarations of conformity from AI vendors are expected in 2026 and 2027. Anyone choosing a vendor today should decide not only by feature set, but also by compliance maturity.
Compliance as an opportunity for better recruiting
Looking at the six steps, it becomes clear quickly: this is not about bureaucracy. It's about structures that are good anyway.
Structured evaluation grids reduce bias and speed up decisions.
Vendor due diligence protects you from silent dependencies and keeps tool changes controllable.
Human oversight is not just compliance, it's also quality assurance.
At Refline, we have worked with Swiss HR teams on exactly these structures for 20 years. What the past years have shown us: compliance-ready and everyday-ready aren't two separate things. Structured evaluation is both at once. The EU AI Act demands nothing that good recruiting shouldn't already be doing. It only gives the prompt to start now.
Conclusion
The EU AI Act affects Swiss recruiting on several paths, directly or indirectly. Part of it already applies: the prohibitions under Article 5 since February 2025, the transparency obligations under Article 50 since 2 August 2026. The bulk of the rest, the high-risk obligations, follows on 2 December 2027.
That leaves 16 months. It sounds like a lot, but it isn't, if processes and documentation still have to be built.
Frequently asked questions about the EU AI Act in recruiting
The four questions Swiss HR teams ask us most often about the EU AI Act.
Has the EU AI Act been postponed?
What was postponed are the obligations for high-risk systems under Annex III, from 2 August 2026 to 2 December 2027. The legal basis is Regulation (EU) 2026/1744, in force since 27 July 2026. What was not postponed are the prohibitions under Article 5, applicable since 2 February 2025, and the transparency obligations under Article 50, applicable since 2 August 2026.
What has applied since 2 August 2026?
Since 2 August 2026, the transparency obligations under Article 50 apply. Anyone using a chatbot in the application process must disclose that it is an AI system. For the machine-readable marking of AI-generated content in systems placed on the market before that date, a grace period runs until 2 December 2026.
How high are the fines for an SME?
The EU AI Act sets out three tiers: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for breaches of other obligations, up to EUR 7.5 million or 1% for false information given to authorities. For SMEs and start-ups, Article 99(6) applies the lower of the two figures in each case, for larger companies the higher one.
How do I document evaluation decisions in recruiting traceably?
Traceable means that for every decision the person, the basis and the point in time are identifiable. In practice this works when feedback is collected centrally in the candidate file rather than in individual email threads. In Refline, everyone involved records their evaluation in the same place.
Ready to put your recruiting on structured, documented evaluation foundations? In several places the AI Act asks for the same thing good recruiting needs anyway: an evaluation you can still justify later. Our free interview guide includes a proven evaluation grid, prepared question sets for structured interviews and example scenarios for the field. It's the foundation our Refline customers have been building on for years.
Want to see first how collecting feedback in the candidate file actually looks? Take a look at Refline in a short demo